Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change.
Users are recommended to upgrade to version 3.2.1, which fixes this issue.
Users are recommended to upgrade to version 3.2.1, which fixes this issue.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vjqc-g788-f378 | Session Fixation Apache DolphinScheduler |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 18 Mar 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache dolphinscheduler |
|
| CPEs | cpe:2.3:a:apache:dolphinscheduler:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache dolphinscheduler |
Thu, 29 Aug 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-384 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-29T15:08:36.166Z
Reserved: 2023-12-06T02:25:09.094Z
Link: CVE-2023-50270
Updated: 2024-08-02T22:16:46.169Z
Status : Analyzed
Published: 2024-02-20T10:15:08.140
Modified: 2025-03-18T17:38:29.743
Link: CVE-2023-50270
No data.
OpenCVE Enrichment
No data.
Github GHSA